I’ve been thinking a lot about identity and autonomy in Web3 lately, especially after seeing the NEAR co-founder’s statement that “the users of blockchain will be AI agents.” It’s a compelling vision—AI on the front-end, blockchain on the back-end, with agents autonomously transacting in a -5 trillion agentic commerce market by 2030.
Then World (Sam Altman’s identity project) launched AgentKit this month, integrating with Coinbase’s x402 protocol to enable AI agents to carry cryptographic proof they’re backed by a verified human. On the surface, this seems like the missing piece: solve bot spam and Sybil attacks while enabling autonomous agent commerce.
But here’s where I’m conflicted.
World ID requires biometric verification via their Orb device—an iris scan that creates an irreversible digital identity tied to your biometric fingerprint. They use zero-knowledge proofs to verify without exposing raw data, which sounds privacy-preserving. But World still collects and manages a centralized biometric database.
The Philosophical Tension
If blockchain’s core value proposition is permissionless access and censorship resistance, what happens when AI agents—supposedly autonomous economic actors—need to prove they’re linked to a biometrically verified human?
Are they truly autonomous? Or are they just extensions of human identity, operating under surveillance infrastructure?
This isn’t hypothetical hand-wraving. As Michael Will, a German data regulator, said: “Once somebody has your specific iris picture, you’ll never have the possibility to stay anonymous.”
The Governance Question
From a DAO governance perspective, here’s what concerns me:
Centralized control: World’s biometric database is centralized under the Worldcoin Foundation and its partners. Even hashed, it’s still controlled by a single entity. Who governs this? What if it’s breached, subpoenaed, or weaponized?
Irreversibility: You can reset a password or rotate a private key. You cannot un-scan your iris. Once it’s captured, that’s permanent. Forever.
Regulatory resistance: Spain’s data protection authority issued a formal warning in February 2026 (GDPR Article 9 violations). Kenya suspended operations over privacy concerns. Uganda saw ethical backlash over young people scanning irises for small crypto amounts—informed consent questions everywhere.
Code is Law, But Community is Constitution
I believe decentralization is a spectrum, not a binary. Progressive decentralization means we start centralized and move toward community control over time.
But biometric databases don’t fit this model. You can’t progressively decentralize iris scans—they’re inherently centralized by their nature (single identity, single database).
The Real Question
Should Web3 embrace agent-human linkage as a necessary compromise (solve spam, fraud, Sybil attacks)? Or resist biometric requirements to preserve our permissionless ethos?
Alternative approaches exist: social graph vouching, proof-of-personhood without biometrics, reputation systems. These are harder to build, slower to scale, but maintain user sovereignty.
What’s the minimum viable identity layer for AI agents? Do we need iris scans? Or just “proof you’re a unique human” without centralized biometric surveillance?
Every voice matters in a true DAO. I’d love to hear how others are thinking about this trade-off between security/spam prevention and permissionless autonomy. ![]()